A vulnerability (CVE-2022-3140) has been identified in the LibreOffice suite that allows for arbitrary scripts to be executed when clicking on a specially prepared link in a document or when a specific event is triggered during document operation. The issue has been resolved in the updates to LibreOffice 7.3.6 and 7.4.1.
The vulnerability is caused by the addition of support for an additional macro invocation scheme 'vnd.libreoffice.command', specific to LibreOffice. This scheme can also be used in URIs employed for integrating LibreOffice with proxy server MS SharePoint. An attacker can exploit such URIs to create links that invoke any internal macros with arbitrary arguments. When clicked or activated by an event in the document, such links can be used to launch scripts without warning the user.
Source: opennet.ru
